Vulnerabilities (CVE)

Filtered by CWE-79
Total 47190 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-18682 2026-08-12 2.6 LOW 3.1 LOW
A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api/upload of the component File Upload API. The manipulation of the argument File results in cross site scripting. The attack may be performed from remote. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-65517 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.
CVE-2026-28141 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
CVE-2026-28143 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
CVE-2026-66711 2026-08-12 N/A 7.1 HIGH
Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.
CVE-2026-28179 2026-08-12 N/A 5.9 MEDIUM
Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
CVE-2026-28082 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
CVE-2026-66703 2026-08-12 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
CVE-2026-61982 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
CVE-2026-66706 2026-08-12 N/A 5.9 MEDIUM
Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
CVE-2026-65509 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
CVE-2026-28178 2026-08-12 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
CVE-2026-65560 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.
CVE-2026-66702 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
CVE-2026-28177 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
CVE-2026-66664 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.
CVE-2026-65545 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.
CVE-2026-66707 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
CVE-2026-66439 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.
CVE-2026-66690 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.